CVE-2026-62832: Windows User Profile Service Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.
CSIRTS triage
- What
- Improper link following in Windows User Profile Service allows privilege escalation.
- Who is affected
- Authorized attackers on local systems running affected Windows versions.
- Urgency
- High severity (CVSS 7.8) but not currently exploited; patch at next maintenance window.
- Action
- Apply the latest Windows security update addressing CVE-2026-62832.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Windows User Profile Service
Get an email when a new Windows User Profile Service advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62832
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-628322.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 82% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-62832 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Windows User Profile
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-62832: Improper link resolution before file access ('link following') in Windows User Profile Service…nvd · 2026-08-11
- highCVE-2026-50425: Use after free in Windows Internal System User Profile allows an authorized attacker to elevat…nvd · 2026-07-14
- highCVE-2026-50425: Windows Internal System User Profile Elevation of Privilege Vulnerabilitymsrc · 2026-07-14
- criticalexploitedCVE-2022-21919: Microsoft Windows User Profile Service Privilege Escalation Vulnerabilitycisa-kev · 2022-04-25
- criticalexploitedCVE-2022-26904: Microsoft Windows User Profile Service Privilege Escalation Vulnerabilitycisa-kev · 2022-04-25
- criticalexploitedCVE-2021-34484: Microsoft Windows User Profile Service Privilege Escalation Vulnerabilitycisa-kev · 2022-03-31
More from Microsoft Security Response Center
- highCVE-2026-70130: Microsoft Office Remote Code Execution Vulnerability2026-08-11
- highCVE-2026-70354: .NET Core Remote Code Execution Vulnerability2026-08-11
- highCVE-2026-68792: Microsoft Office Elevation of Privilege Vulnerability2026-08-11
- highCVE-2026-66807: Microsoft Office Graphics Component Remote Code Execution Vulnerability2026-08-11
- highCVE-2026-64909: Microsoft Office Remote Code Execution Vulnerability2026-08-11